Blocking public access to our servers

I’m deploying an SOA stack which shouldn’t be accessible publicly, just from our main app. What’s the best way to set that up? I know that my servers all use private networking within the same stack, but this is outside the stack.

You can use the command line toolbelt to set the allowed.web.source on the stack. That will mean that only the matches will be allowed to your web ports by default.

